CMMC Level 2 still runs on the 110 security requirements in NIST SP 800-171 Rev.2, and that baseline has not moved. Following the Department of Defense's July 13, 2026 suspension of Phase II, most new contract requirements point to Level 2 (Self), recorded in SPRS rather than a third-party C3PAO assessment. Contractors still need to confirm the exact assessment type named in their solicitation, and DFARS 252.204-7012 safeguarding duties apply no matter what the level says.
TL;DR:
- Most new contracts now require self-assessment of CMMC Level 2, with verification submitted via SPRS, not third-party assessments, unless specified otherwise in the solicitation.
- Contractors must provide current, date-specific evidence for each control family, focusing on actual logs, configuration documents, and training records, not just policies.
- Assessment type depends on solicitation language and SPRS references; verify assessment requirements in writing before compliance efforts begin.
- SPRS status is valid for three years with annual affirmations; failure to update or revalidate can lead to disqualification from contracts or options.
- Despite the suspension of Phase II, safeguarding obligations under DFARS 252.204-7012 remain enforceable, prohibiting contractors from neglecting security controls or misrepresenting compliance.
Table of Contents
- What Are the CMMC Level 2 Requirements Today?
- Which CMMC Level 2 Assessment Type Applies to You?
- How Long Does a CMMC Level 2 Status Last?
- POA&Ms, Scoring Thresholds, and What You Cannot Defer
- Building an Evidence File That Survives an Assessment
- Does DFARS 252.204-7012 Still Apply After the CMMC Pause?
- Your CMMC Level 2 Readiness Roadmap
- Why Full Compliance Still Matters During the Suspension
- A Managed Path to CMMC Level 2 Readiness
- Where to Verify These CMMC Level 2 Rules Yourself
- Sources
What Are the CMMC Level 2 Requirements Today?
Nothing about the underlying control set changed on July 13, 2026. CMMC Level 2 requirements still map directly to the 110 security requirements in NIST SP 800-171 Rev.2, organized into 14 control families. What changed is who is checking your work and how often a third party gets involved.
Each control family covers a distinct slice of your security program, and assessors expect to see evidence tied to a specific date, system, and person responsible, not a policy binder that says the right things in the abstract.
- Access Control (AC): Who can reach CUI, and under what conditions. Assessors want current access lists, role-based permission matrices, and screenshots of failed login lockout settings.
- Awareness and Training (AT): Annual security training completion records with names, dates, and course content, not just a vendor certificate of completion.
- Audit and Accountability (AU): Log retention policies plus actual log samples showing who did what and when, ideally pulled from a SIEM or centralized log manager.
- Configuration Management (CM): Baseline configuration documents and change records showing deviations were approved, tracked, and reversed if unauthorized.
- Identification and Authentication (IA): Multi-factor authentication configuration screenshots for remote access and privileged accounts, dated within the assessment window.
- Incident Response (IR): A written incident response plan plus records from at least one tabletop exercise or real incident, including lessons-learned notes.
- Maintenance (MA): Records of who performed system maintenance, remote or on-site, and what controls governed that access.
- Media Protection (MP): Sanitization and destruction logs for any media that once held CUI.
- Personnel Security (PS): Termination checklists showing account deactivation timed to an employee's last day.
- Physical Protection (PE): Visitor logs and access-control records for facilities housing CUI systems.
- Risk Assessment (RA): A current risk assessment report, updated at least annually, with findings tracked to closure.
- Security Assessment (CA): Internal assessment results and a System Security Plan (SSP) that assessors can cross-reference line by line.
- System and Communications Protection (SC): Network diagrams and encryption configuration for data in transit and at rest.
- System and Information Integrity (SI): Patch management records and anti-malware alert logs showing detection and response times.
One out of every 14 control families deals directly with monitoring and detection (AU and SI combined), yet these two families generate more assessment findings than any other pairing because contractors tend to write the policy and skip the ongoing evidence trail.
Note that NIST SP 800-171 Revision 3 exists and restructures the requirement count, but it is not the controlling standard for CMMC assessments right now. DoD has not completed the rulemaking needed to shift the baseline, so Rev.2's 110 requirements remain the operative target. Building your program against Rev.3 today would mean rework later if the transition timeline slips, which it has before.

Which CMMC Level 2 Assessment Type Applies to You?
The 2026 suspension didn't erase the two assessment paths. It just narrowed which one applies to most new work.
Level 2 (Self) means your organization performs its own assessment against the 110 requirements, scores itself, and submits results to the Supplier Performance Risk System (SPRS). No outside assessor reviews your evidence before the score goes on record, though the government can audit that self-attestation later.
Level 2 (C3PAO) requires a Department-authorized third-party assessment organization to conduct the review, verify evidence, and submit a certified assessment result, typically feeding into a CMMC eMASS record rather than a straight SPRS self-entry.
Here's what actually shifted on July 13, 2026: the Department suspended Phase II implementation and directed program offices not to designate new C3PAO requirements during the review period. In practice, that means most new solicitations issued now will call for Level 1 (Self) or Level 2 (Self), not a certified third-party assessment, unless a future rule reverses that direction.
That does not mean every contract you're bidding defaults to self-assessment. Existing contracts that already specified Level 2 (C3PAO) may still carry that requirement forward, and some program offices retain discretion depending on the sensitivity of the work. Confirm your specific obligation with these steps:
- Read the solicitation's cybersecurity clause language directly. Look for explicit references to "Level 2 (C3PAO)" versus "Level 2 (Self)" rather than assuming based on contract value or CUI volume.
- Check the SPRS scoring requirement referenced in the RFP. If it cites a self-assessment score submission process, that's a strong signal you're on the self-assessment track.
- Request written confirmation from the contracting officer. Email is fine, but get the assessment type stated in writing before you build a compliance program around the wrong path.
- Ask your prime, if you're a subcontractor, what flowdown language appears in your subcontract. Primes sometimes impose a higher assessment bar than the government requires of them.
- Revisit that confirmation before each renewal or option period. Assessment-type requirements can change between contract years, especially while the Reform Task Force reviews Phase II.
The assessment type matters more for your budget and timeline than the level number itself. Both paths test against the identical 110 requirements. The difference is who validates your evidence and where that validation lives on record.
How Long Does a CMMC Level 2 Status Last?
A Level 2 status, whether self-assessed or C3PAO-certified, is valid for three years. That sounds like a long runway until you realize the government doesn't let you set it and forget it for those three years.
Contractors must submit an annual affirmation confirming continued compliance with the same 110 requirements, signed by a senior company official, every year the three-year status is active. Miss that affirmation window and your status can lapse even though the underlying three-year clock hasn't run out.
Posting works like this in practice:
- The Organization Seeking Assessment (OSA) enters its self-assessment score and supporting summary information directly into SPRS.
- The system assigns a CMMC Unique Identifier (UID) tied to that specific assessment record, which contracting officers reference during award decisions.
- Annual affirmations get logged against that same UID, creating a running compliance timeline a contracting officer can pull up during a review.
- A missed affirmation, an expired three-year window, or a status downgrade can all trigger contract eligibility problems, including disqualification from award or exercise of an option period.
The paperwork discipline here is not optional busywork. A contracting officer who can't verify your current SPRS status has every reason to treat your bid as noncompliant, and that's a fast way to lose work you were otherwise qualified for.
POA&Ms, Scoring Thresholds, and What You Cannot Defer
CMMC Level 2 allows limited use of a Plan of Action and Milestones (POA&M) for requirements you haven't fully implemented yet, but the rules are tighter than most contractors expect.
To qualify for Conditional status, your self-assessment or C3PAO score must reach at least 0.80 out of the maximum possible score across the 110 requirements. Score below that threshold and you don't get a POA&M option at all. You simply fail the assessment.
Even above that threshold, certain requirements can never go on a POA&M. Controls governing external connections and physical access logging for systems handling CUI are treated as non-deferrable, meaning they must be fully implemented before you can claim Conditional status, not just planned. A handful of other high-risk controls, generally those tied to access boundary enforcement and authentication, follow the same rule.
Practical examples of requirements that typically cannot sit on a POA&M:
- Boundary protection controls governing external network connections (SC family)
- Multi-factor authentication for privileged and remote access (IA family)
- Physical access logging for facilities or areas housing CUI systems (PE family)
Pro Tip: Run your own gap assessment against the 0.8 threshold before you submit anything to SPRS. A score of 0.75 doesn't just mean "close." It means no Conditional status, no POA&M, and a hard stop until you close the gap.
Once Conditional status is granted, you get 180 days to close every open POA&M item and reach full compliance. Miss that window and your status reverts, which can trigger the same contract eligibility consequences as never having achieved compliance at all. There's no informal extension process here. Build your remediation plan around that 180-day clock from day one, not from the day you start worrying about it.
Building an Evidence File That Survives an Assessment
Assessors don't take your word for it. They want artifacts, and the DoD's Level 2 Assessment Guide spells out what "sufficient evidence" actually looks like for each of the 110 requirements.
Start with your System Security Plan (SSP). At minimum, it needs to describe your system boundary, list every one of the 110 requirements with an implementation statement, and cross-reference the specific evidence artifact that proves each claim. A generic SSP copied from a template without those direct evidence links is one of the fastest ways to fail an assessment, self-run or otherwise.
Beyond the SSP, build your evidence file around these categories:
- Access and identity records — current user access lists, role assignments, and MFA configuration exports dated within the assessment period.
- Log and monitoring data — SIEM alert review logs, showing not just that alerts fired but that someone reviewed and closed them.
- Configuration baselines — documented baseline configs for servers, endpoints, and network devices, plus a change log showing deviations were caught.
- Patch and vulnerability records — scan results and patch deployment timestamps that show a consistent remediation cadence, not a one-time cleanup before assessment day.
- Training completion records — names, dates, and course content for annual security awareness training, tied to your personnel roster.
- Incident response exercise records — documentation from a tabletop exercise or a real incident, including what was learned and what changed afterward.
Contractors who fail their first self-assessment attempt most often fail on evidence quality, not control design — they implemented the control but never documented it in a way a third party could independently verify.
Label every artifact with the date, system name, and the specific requirement number it supports. Retain evidence for at least the length of your three-year assessment cycle, and longer if your contract or prime requires it. A tool like a managed 24/7 security operations center can handle the log review and alert documentation piece continuously, so you're not scrambling to reconstruct six months of SIEM history the week before a SPRS submission.
Does DFARS 252.204-7012 Still Apply After the CMMC Pause?
Yes, without exception. DFARS 252.204-7012 requires contractors to safeguard covered defense information and report cyber incidents within 72 hours of discovery, and that clause was never suspended. The July 13, 2026 pause affected CMMC Phase II implementation specifically. It did not touch the underlying contractual safeguarding requirement that's been in force for years.
This distinction trips up a lot of contractors. CMMC assessments verify compliance with NIST SP 800-171. DFARS 252.204-7012 is the contractual obligation that requires that compliance in the first place. Pausing the verification mechanism doesn't pause the underlying duty.
For subcontractors, the practical challenge is flowdown language. If your prime's contract includes 252.204-7012, that obligation typically flows down to you regardless of your tier, and Level 3 prime contracts generally set Level 2 (C3PAO) as the default minimum subcontractor requirement unless the Department specifies otherwise. Don't assume your prime's higher-level requirement excuses you from anything.
Steps to protect yourself contractually:
- Request the specific flowdown clauses in writing from your prime, not a verbal assurance that "you're covered."
- Ask your prime directly which CMMC level and assessment type applies to your specific scope of work.
- Get contracting officer confirmation on assessment type before you invest in a compliance path that turns out to be the wrong one.
- Document every one of these confirmations in your contract file, because a verbal answer won't help you six months later when a new contracting officer takes over.
Your CMMC Level 2 Readiness Roadmap
Getting to a defensible Level 2 status is a sequence, not a sprint, and skipping steps almost always costs more time later than it saves now.
- Scope your CUI environment. Identify every system, application, and data flow that touches Controlled Unclassified Information. Get this wrong and you'll either over-invest in securing systems that don't need it or under-invest in systems that do.
- Run a gap assessment against all 110 requirements. Score yourself honestly against the same criteria a real assessment would use, including the 0.8 Conditional status threshold.
- Draft or update your SSP. Every requirement needs an implementation statement tied to a specific evidence artifact, not a paragraph of good intentions.
- Prioritize remediation by risk and deferability. Fix the non-deferrable requirements first (external connections, MFA, physical access logging), since those can't ride on a POA&M regardless of your overall score.
- Collect and organize evidence continuously, not in a two-week scramble before submission.
- Run an internal dry-run assessment using the same evidence file and scoring method you'll use for the real submission.
- Submit your self-assessment score and summary to SPRS, then set a calendar reminder for your annual affirmation, not just your three-year renewal.
Timeline expectations vary widely by organization size and existing maturity. Practitioner estimates put typical readiness timelines at 2 to 9 months, with smaller organizations that already have decent IT hygiene on the shorter end and larger, more complex environments, or those starting from a weak security baseline, stretching toward the longer end.
Pro Tip: Don't treat POA&M eligibility as a planning strategy. Aim to fully implement as many requirements as possible before your assessment date, and reserve POA&M status for genuine edge cases. Contractors who plan around POA&Ms from the start often find themselves scrambling against the 180-day closeout clock with less runway than they assumed.
External help, whether that's a consultant, a managed compliance partner, or an internal hire dedicated to the effort, tends to shorten the gap-assessment and evidence-collection phases the most, since those are the steps where inexperienced teams lose the most time second-guessing what "sufficient evidence" actually looks like.
Why Full Compliance Still Matters During the Suspension
The July 13, 2026 suspension is a regulatory process event. It is not a security exemption, and treating it as one is the single most expensive misreading of this update I've seen contractors make in the weeks since.
Here's the thing people miss: DFARS 252.204-7012 never paused. Your contractual duty to safeguard CUI and report incidents within 72 hours exists independent of whatever assessment mechanism verifies it. Legal commentary on the suspension has specifically warned against "compliance drift" during review periods like this one, and for good reason. Programs get reformed. Rules get reinstated, sometimes with retroactive expectations attached. Letting your controls lapse now because "the assessment isn't required yet" is a bet that the review period ends exactly the way you hope it does.
There's also a sharper risk hiding under the surface: False Claims Act exposure. If you affirm compliance in SPRS or represent your security posture in a contract certification and that representation turns out to be false, the suspension of Phase II assessments does nothing to shield you from that liability. The assessment mechanism paused. The consequences of misrepresentation did not.
The contractors who come out ahead here aren't the ones who relaxed. They're the ones who used the pause to tighten their evidence trail, so that whenever the next rule lands, they're documenting from a position of strength instead of starting from zero.
— Danny
A Managed Path to CMMC Level 2 Readiness
Building a defensible Level 2 posture in-house means juggling SSP documentation, continuous log review, MFA configuration audits, and SPRS submission timing, on top of whatever your actual mission is. A managed service can help compliance officers avoid becoming full-time CMMC specialists and get this right.

Marfi's CMMC and NIST SP 800-171 readiness services map directly to the roadmap above: scoping your CUI environment, drafting an SSP that links every requirement to real evidence, and prioritizing remediation around the non-deferrable controls first. The 24/7 security operations center handles the ongoing log review and alert documentation that assessors actually want to see, not a one-time snapshot. And because Marfi runs compliance as an accountable team rather than a patchwork of vendors, the same group tracking your continuous GRC posture is the one helping you post and affirm your status in SPRS every year.
If you're not sure whether your solicitation calls for Level 2 (Self) or C3PAO, or you want your evidence file audit-ready before the next contracting officer asks for it, request a CMMC readiness assessment and get a clear picture of where your gaps sit today.
Where to Verify These CMMC Level 2 Rules Yourself
Every rule in this guide traces back to a primary government source, and you should check them directly rather than relying on secondhand summaries, including this one, when a contract decision is on the line.
Start with the DoD CIO's official CMMC program page for the current baseline and program status, and the Level 2 Assessment Guide (Version 2.13) for assessment procedures and evidence expectations. The DFARS 252.204-7012 clause text on acquisition.gov confirms your ongoing safeguarding obligations, and the Federal Register's CMMC program entries track formal rulemaking changes as they happen. These are the legally authoritative sources. Everything else, including practitioner guides, is interpretation.
Sources
- About CMMC - DoD CIO
- Forging the Arsenal of Freedom: DoD Suspends CMMC Phase II Requirements - U.S. Department of Defense
- CMMC 2.0 Requirements 2026: Levels, Cost & What Changed - The Defense Compliance Report
